ISC StormCast for Friday, March 17th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 March 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, March 17th, 2017 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich. |
| 0:09.4 | And I'm recording from Jacksonville, Florida. |
| 0:12.8 | German security company SEC Consult did release details about rather easy to exploit vulnerability in various ubiquity equipment. |
| 0:24.2 | Epicvity makes a lot of wireless equipment, a lot of carrier equipment as well. This bug does affect |
| 0:32.1 | a lot of the point-to-point link systems and the like. There's a long list of vulnerable devices in the advisory. |
| 0:40.3 | It does, by the way, not affect the very popular Unify line of equipment that is also being sold by Obiquity. |
| 0:50.6 | Now, this particular vulnerability takes advantage of really two flaws. |
| 0:55.0 | First of all, these devices do run a very outdated version of PHP, |
| 1:01.0 | PHP version 2. |
| 1:04.0 | Now, this version of PHP makes it relatively easy to inject commands into PHP code. |
| 1:12.1 | That is being exploited here, but in itself this may not have been really all that bad, |
| 1:17.9 | given that you have to authenticate. |
| 1:19.8 | The second problem here is that there is no cross-site request forging protection. |
| 1:25.5 | So a victim would log in to one of these devices not log out and then visit a website |
| 1:33.3 | that would trick the victim's browser into injecting a command into the Big Viti device. |
| 1:40.3 | There is proof of concept, exploit code out there, and demo videos that demonstrate how this can be used to install a shell, a remote shell, on these vulnerable devices. |
| 1:53.0 | No patch from Obikvety at this point, and sadly, Obiquity seems to have bunged a little bit the response to the vulnerability report |
| 2:02.6 | here. It was originally reported via Hacker 1, a bug bounty site that Obiquity participates in last November. |
| 2:12.2 | And Darknet Intelligence Company, Six Gill is reporting about an interesting new remote access tool for |
| 2:19.7 | Mac OS. |
| 2:21.1 | Apparently, it's being offered for sale on underground forums. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

